You can try adding the following firewall rules.
iptables -I FORWARD -m conntrack --ctstate DNAT -j ACCEPT